All case studies
Compliance

Endpoint compliance overhaul

How a Riyadh FinTech firm went from failing audits to 99% compliance in six weeks.

Industry

Financial services

Location

Riyadh, Saudi Arabia

Duration

6 weeks

99%

endpoint compliance

100%

audit pass rate

6 wks

to audit-ready

Endpoint compliance overhaul

A Riyadh-based FinTech company was consistently failing internal and third-party security audits. With SAMA (Saudi Central Bank) and NCA (National Cybersecurity Authority) requirements tightening, the stakes were high — and the problem was clear: unmanaged, unencrypted laptops on a corporate network that held sensitive financial data.

The challenge

The challenge

Employees were using personal Microsoft accounts on corporate devices. There was no BitLocker encryption, no MDM enrollment, and no way to verify that a device met minimum security standards before it connected to internal systems. Auditors had flagged the same issues repeatedly, and the company was running out of time to address them.

  • Devices not enrolled in any MDM or management platform
  • No BitLocker encryption enforced across the fleet
  • Repeated SAMA and NCA audit failures
  • No live compliance visibility for leadership

What we built

What we built

Logistructure enrolled every corporate device into Microsoft Intune, enforced BitLocker full-disk encryption across all Windows machines, and built a compliance policy framework aligned specifically to SAMA and NCA requirements. A real-time compliance dashboard gave leadership a live view of every device — replacing guesswork with evidence.

  1. 1

    Device inventory & gap analysis

    Catalogued every device on the network, identified unmanaged endpoints, and mapped gaps against SAMA and NCA control requirements.

  2. 2

    Intune enrollment & tenant hardening

    Enrolled all devices into Intune, migrated from personal to corporate accounts, and applied conditional access policies to block non-compliant devices from sensitive systems.

  3. 3

    BitLocker encryption rollout

    Enforced BitLocker full-disk encryption via Intune policy across 100% of Windows devices, with keys escrowed securely in Azure AD.

  4. 4

    SAMA/NCA compliance baselines

    Configured compliance policies mapped directly to SAMA Cyber Security Framework and NCA ECC-1:2018 controls — defensible in any audit.

  5. 5

    Live dashboard & automated reporting

    Built a real-time compliance dashboard for leadership and configured automated audit reports that pull directly from Intune — ready to share at any point.

The results

The results

Within six weeks of kickoff, the company passed its next third-party audit with a 100% pass rate — the first clean audit in over two years. Every device on the network is now encrypted, enrolled, and verified as compliant before it can access any internal system.

99%

endpoint compliance

100%

third-party audit pass

6 wks

from kickoff to clean

100%

devices encrypted

We went from dreading audits to actually welcoming them. Every device is encrypted, every policy is enforced, and we have the reports to prove it.

Nasser Al-Ghamdi

CISO, FinTech Company, Riyadh

Let's build it together

Ready to transform your IT?

Tell us about your fleet and where you're stuck. We'll map the path to secure, well-managed devices your team can actually rely on.